You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Unshared secrets:_fingerprint_matcher only knows the codex32 fingerprint identifier. Use identifier_origin() from gui: Require the recorded fingerprint before import #28 so that legacy Bails identifiers also break ties. Those rules use the first three characters of a hash of the seed: RIPEMD-160, or SHA-256 for the mid-2023 alpha. A candidate passes if any rule matches. Don't apply the rules one after another.
Shares: when a threshold of cards is present and one is damaged, recover the seed from each candidate and rank by the same test. This covers legacy Bails split backups, whose paper cards are all shares carrying the seed-derived identifier. These are backups made before Bails moved to the python-codex32 GUI (Bails commit 75cc7c4, 2026-09-29). Current Bails and python-codex32 give shared sets random identifiers, so the test can't rank those.
Ranking only: it never widens the search or counts as checksum strength. The operator still confirms.
_fingerprint_matcheronly knows the codex32 fingerprint identifier. Useidentifier_origin()from gui: Require the recorded fingerprint before import #28 so that legacy Bails identifiers also break ties. Those rules use the first three characters of a hash of the seed: RIPEMD-160, or SHA-256 for the mid-2023 alpha. A candidate passes if any rule matches. Don't apply the rules one after another.